nextjs-supabase-auth

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive security guidance, specifically warning against insecure authentication methods such as getSession() in favor of the more secure getUser(), which involves server-side validation.
  • [SAFE]: Includes a structured reference system (validations.md, sharp_edges.md) designed to audit and correct common implementation errors, demonstrating a defensive security posture.
  • [SAFE]: Environment variable usage for Supabase configuration (NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_ANON_KEY) follows standard security practices for public keys in client-side frameworks.
  • [SAFE]: Dependency on @supabase/ssr refers to an official, well-known library for Supabase integration, posing no supply chain risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 03:54 PM
Security Audit — agent-trust-hub — nextjs-supabase-auth